manage.php 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405
  1. <?php
  2. // DEPRECATED: The bundled update server is deprecated and unmaintained.
  3. // It is kept for reference only and will be removed in a future release.
  4. // Do not deploy it for new installations.
  5. declare(strict_types=1);
  6. $baseDir = __DIR__;
  7. $configFile = $baseDir . "/config.php";
  8. $manifestFile = $baseDir . "/manifest.json";
  9. $packagesDir = $baseDir . "/packages";
  10. if (is_file($configFile)) {
  11. require_once $configFile;
  12. }
  13. if (session_status() === PHP_SESSION_NONE) {
  14. ini_set("session.use_strict_mode", "1");
  15. ini_set("session.cookie_httponly", "1");
  16. ini_set("session.cookie_samesite", "Lax");
  17. session_start();
  18. }
  19. $messages = [];
  20. $errors = [];
  21. function updateManageEscape($value): string
  22. {
  23. return htmlspecialchars((string) $value, ENT_QUOTES, "UTF-8");
  24. }
  25. function updateManageVersionIsValid(string $version): bool
  26. {
  27. return preg_match('/^v\d+\.\d+\.\d+$/', $version) === 1;
  28. }
  29. function updateManagePasswordConfigured(): bool
  30. {
  31. return defined("UPDATE_SERVER_PASSWORD_HASH") || defined("UPDATE_SERVER_PASSWORD");
  32. }
  33. function updateManagePasswordMatches(string $password): bool
  34. {
  35. if (defined("UPDATE_SERVER_PASSWORD_HASH")) {
  36. return password_verify($password, (string) UPDATE_SERVER_PASSWORD_HASH);
  37. }
  38. if (defined("UPDATE_SERVER_PASSWORD")) {
  39. return hash_equals((string) UPDATE_SERVER_PASSWORD, $password);
  40. }
  41. return false;
  42. }
  43. function updateManageIsLoggedIn(): bool
  44. {
  45. return !empty($_SESSION["update_server_logged_in"]);
  46. }
  47. function updateManageCsrfToken(): string
  48. {
  49. if (empty($_SESSION["update_server_csrf_token"])) {
  50. $_SESSION["update_server_csrf_token"] = bin2hex(random_bytes(32));
  51. }
  52. return $_SESSION["update_server_csrf_token"];
  53. }
  54. function updateManageCsrfIsValid(string $token): bool
  55. {
  56. return !empty($_SESSION["update_server_csrf_token"]) &&
  57. hash_equals($_SESSION["update_server_csrf_token"], $token);
  58. }
  59. function updateManageEnsureDirectory(string $dir): void
  60. {
  61. if (!is_dir($dir) && !mkdir($dir, 02775, true) && !is_dir($dir)) {
  62. throw new RuntimeException("Directory cannot be created: " . $dir);
  63. }
  64. @chmod($dir, 02775);
  65. }
  66. function updateManageReadManifest(string $manifestFile): array
  67. {
  68. if (!is_file($manifestFile)) {
  69. return ["latest" => "", "releases" => []];
  70. }
  71. $decoded = json_decode((string) file_get_contents($manifestFile), true);
  72. if (!is_array($decoded)) {
  73. throw new RuntimeException("Manifest is not valid JSON.");
  74. }
  75. return [
  76. "latest" => trim((string) ($decoded["latest"] ?? "")),
  77. "releases" => isset($decoded["releases"]) && is_array($decoded["releases"])
  78. ? $decoded["releases"]
  79. : [],
  80. ];
  81. }
  82. function updateManageWriteManifest(string $manifestFile, array $manifest): void
  83. {
  84. $json = json_encode(
  85. $manifest,
  86. JSON_PRETTY_PRINT | JSON_UNESCAPED_SLASHES | JSON_UNESCAPED_UNICODE,
  87. );
  88. if ($json === false) {
  89. throw new RuntimeException("Manifest cannot be encoded.");
  90. }
  91. $tmpFile = $manifestFile . ".tmp";
  92. if (file_put_contents($tmpFile, $json . PHP_EOL, LOCK_EX) === false) {
  93. throw new RuntimeException("Manifest cannot be written.");
  94. }
  95. @chmod($tmpFile, 0664);
  96. if (!rename($tmpFile, $manifestFile)) {
  97. @unlink($tmpFile);
  98. throw new RuntimeException("Manifest cannot be saved.");
  99. }
  100. @chmod($manifestFile, 0664);
  101. }
  102. function updateManagePackageFileName(string $version): string
  103. {
  104. return "psa-orderform-" . $version . ".zip";
  105. }
  106. function updateManageUploadedFileIsZip(array $file): bool
  107. {
  108. $name = strtolower((string) ($file["name"] ?? ""));
  109. $tmpName = (string) ($file["tmp_name"] ?? "");
  110. if (!str_ends_with($name, ".zip") || !is_uploaded_file($tmpName)) {
  111. return false;
  112. }
  113. $handle = fopen($tmpName, "rb");
  114. if ($handle === false) {
  115. return false;
  116. }
  117. $signature = fread($handle, 4);
  118. fclose($handle);
  119. return $signature === "PK\x03\x04" || $signature === "PK\x05\x06" || $signature === "PK\x07\x08";
  120. }
  121. function updateManagePublishUpload(
  122. string $version,
  123. array $file,
  124. string $manifestFile,
  125. string $packagesDir,
  126. ): void {
  127. if (!updateManageVersionIsValid($version)) {
  128. throw new RuntimeException("Version must use the format vX.Y.Z.");
  129. }
  130. if (($file["error"] ?? UPLOAD_ERR_NO_FILE) !== UPLOAD_ERR_OK) {
  131. throw new RuntimeException("Upload failed with error code " . (string) ($file["error"] ?? "unknown") . ".");
  132. }
  133. if (!updateManageUploadedFileIsZip($file)) {
  134. throw new RuntimeException("Uploaded file must be a ZIP package.");
  135. }
  136. updateManageEnsureDirectory($packagesDir);
  137. $fileName = updateManagePackageFileName($version);
  138. $targetPath = $packagesDir . DIRECTORY_SEPARATOR . $fileName;
  139. if (!move_uploaded_file((string) $file["tmp_name"], $targetPath)) {
  140. throw new RuntimeException("Uploaded package cannot be stored.");
  141. }
  142. @chmod($targetPath, 0664);
  143. $sha256 = strtolower(hash_file("sha256", $targetPath) ?: "");
  144. $size = filesize($targetPath);
  145. if (!preg_match('/^[a-f0-9]{64}$/', $sha256) || $size === false || $size <= 0) {
  146. @unlink($targetPath);
  147. throw new RuntimeException("Stored package could not be verified.");
  148. }
  149. $manifest = updateManageReadManifest($manifestFile);
  150. $manifest["latest"] = $version;
  151. $manifest["releases"][$version] = [
  152. "version" => $version,
  153. "package" => "packages/" . $fileName,
  154. "sha256" => $sha256,
  155. "size" => $size,
  156. "published_at" => date(DATE_ATOM),
  157. ];
  158. ksort($manifest["releases"]);
  159. updateManageWriteManifest($manifestFile, $manifest);
  160. }
  161. function updateManageSetLatest(string $version, string $manifestFile): void
  162. {
  163. if (!updateManageVersionIsValid($version)) {
  164. throw new RuntimeException("Invalid release version.");
  165. }
  166. $manifest = updateManageReadManifest($manifestFile);
  167. if (!isset($manifest["releases"][$version])) {
  168. throw new RuntimeException("Release is not present in the manifest.");
  169. }
  170. $manifest["latest"] = $version;
  171. updateManageWriteManifest($manifestFile, $manifest);
  172. }
  173. function updateManageDeleteRelease(
  174. string $version,
  175. string $manifestFile,
  176. string $baseDir,
  177. ): void {
  178. if (!updateManageVersionIsValid($version)) {
  179. throw new RuntimeException("Invalid release version.");
  180. }
  181. $manifest = updateManageReadManifest($manifestFile);
  182. if (!isset($manifest["releases"][$version])) {
  183. throw new RuntimeException("Release is not present in the manifest.");
  184. }
  185. $package = trim((string) ($manifest["releases"][$version]["package"] ?? ""));
  186. unset($manifest["releases"][$version]);
  187. if ($manifest["latest"] === $version) {
  188. $manifest["latest"] = "";
  189. }
  190. updateManageWriteManifest($manifestFile, $manifest);
  191. if ($package !== "" && !str_contains($package, "\0") && !str_starts_with($package, "/")) {
  192. $packagePath = realpath($baseDir . "/" . $package);
  193. $packagesPath = realpath($baseDir . "/packages");
  194. if (
  195. $packagePath !== false &&
  196. $packagesPath !== false &&
  197. str_starts_with($packagePath, $packagesPath . DIRECTORY_SEPARATOR) &&
  198. is_file($packagePath)
  199. ) {
  200. unlink($packagePath);
  201. }
  202. }
  203. }
  204. if ($_SERVER["REQUEST_METHOD"] === "POST") {
  205. $action = (string) ($_POST["action"] ?? "");
  206. if ($action === "login") {
  207. if (!updateManagePasswordConfigured()) {
  208. $errors[] = "No password is configured.";
  209. } elseif (updateManagePasswordMatches((string) ($_POST["password"] ?? ""))) {
  210. session_regenerate_id(true);
  211. $_SESSION["update_server_logged_in"] = true;
  212. $messages[] = "Logged in.";
  213. } else {
  214. $errors[] = "Wrong password.";
  215. }
  216. } elseif ($action === "logout") {
  217. unset($_SESSION["update_server_logged_in"], $_SESSION["update_server_csrf_token"]);
  218. $messages[] = "Logged out.";
  219. } elseif (!updateManageIsLoggedIn()) {
  220. $errors[] = "Login required.";
  221. } elseif (!updateManageCsrfIsValid((string) ($_POST["csrf_token"] ?? ""))) {
  222. $errors[] = "Invalid token. Please reload the page and try again.";
  223. } else {
  224. try {
  225. if ($action === "upload") {
  226. updateManagePublishUpload(
  227. trim((string) ($_POST["version"] ?? "")),
  228. $_FILES["package"] ?? [],
  229. $manifestFile,
  230. $packagesDir,
  231. );
  232. $messages[] = "Release uploaded and published.";
  233. } elseif ($action === "set_latest") {
  234. updateManageSetLatest(trim((string) ($_POST["version"] ?? "")), $manifestFile);
  235. $messages[] = "Latest release updated.";
  236. } elseif ($action === "delete") {
  237. updateManageDeleteRelease(trim((string) ($_POST["version"] ?? "")), $manifestFile, $baseDir);
  238. $messages[] = "Release deleted.";
  239. }
  240. } catch (Throwable $exception) {
  241. $errors[] = $exception->getMessage();
  242. }
  243. }
  244. }
  245. try {
  246. $manifest = updateManageReadManifest($manifestFile);
  247. } catch (Throwable $exception) {
  248. $manifest = ["latest" => "", "releases" => []];
  249. $errors[] = $exception->getMessage();
  250. }
  251. $releases = $manifest["releases"];
  252. krsort($releases);
  253. ?>
  254. <!DOCTYPE html>
  255. <html lang="de">
  256. <head>
  257. <meta charset="UTF-8">
  258. <meta name="viewport" content="width=device-width, initial-scale=1.0">
  259. <title>Update Management</title>
  260. </head>
  261. <body>
  262. <h1>Update Management</h1>
  263. <p><strong>Deprecated:</strong> This update server is no longer maintained and will be removed in a future release.</p>
  264. <?php foreach ($messages as $message): ?>
  265. <p><strong><?php echo updateManageEscape($message); ?></strong></p>
  266. <?php endforeach; ?>
  267. <?php foreach ($errors as $error): ?>
  268. <p><strong>Error:</strong> <?php echo updateManageEscape($error); ?></p>
  269. <?php endforeach; ?>
  270. <?php if (!updateManageIsLoggedIn()): ?>
  271. <form method="POST">
  272. <input type="hidden" name="action" value="login">
  273. <p>
  274. <label for="password">Password</label><br>
  275. <input type="password" id="password" name="password" required>
  276. </p>
  277. <button type="submit">Login</button>
  278. </form>
  279. <?php else: ?>
  280. <form method="POST">
  281. <input type="hidden" name="action" value="logout">
  282. <button type="submit">Logout</button>
  283. </form>
  284. <h2>Upload release</h2>
  285. <form method="POST" enctype="multipart/form-data">
  286. <input type="hidden" name="action" value="upload">
  287. <input type="hidden" name="csrf_token" value="<?php echo updateManageEscape(updateManageCsrfToken()); ?>">
  288. <p>
  289. <label for="version">Version</label><br>
  290. <input type="text" id="version" name="version" required placeholder="v1.3.3" pattern="v[0-9]+\.[0-9]+\.[0-9]+">
  291. </p>
  292. <p>
  293. <label for="package">ZIP package</label><br>
  294. <input type="file" id="package" name="package" accept=".zip,application/zip" required>
  295. </p>
  296. <button type="submit">Upload and publish</button>
  297. </form>
  298. <h2>Current manifest</h2>
  299. <p>Latest: <?php echo updateManageEscape($manifest["latest"] !== "" ? $manifest["latest"] : "none"); ?></p>
  300. <p>Manifest endpoint: <a href="manifest.php">manifest.php</a></p>
  301. <?php if (empty($releases)): ?>
  302. <p>No releases configured.</p>
  303. <?php else: ?>
  304. <table border="1" cellpadding="6" cellspacing="0">
  305. <thead>
  306. <tr>
  307. <th>Version</th>
  308. <th>Package</th>
  309. <th>SHA-256</th>
  310. <th>Size</th>
  311. <th>Published</th>
  312. <th>Actions</th>
  313. </tr>
  314. </thead>
  315. <tbody>
  316. <?php foreach ($releases as $version => $release): ?>
  317. <tr>
  318. <td><?php echo updateManageEscape($version); ?></td>
  319. <td><?php echo updateManageEscape($release["package"] ?? ""); ?></td>
  320. <td><?php echo updateManageEscape($release["sha256"] ?? ""); ?></td>
  321. <td><?php echo updateManageEscape($release["size"] ?? ""); ?></td>
  322. <td><?php echo updateManageEscape($release["published_at"] ?? ""); ?></td>
  323. <td>
  324. <?php if ($manifest["latest"] !== $version): ?>
  325. <form method="POST" style="display:inline">
  326. <input type="hidden" name="action" value="set_latest">
  327. <input type="hidden" name="csrf_token" value="<?php echo updateManageEscape(updateManageCsrfToken()); ?>">
  328. <input type="hidden" name="version" value="<?php echo updateManageEscape($version); ?>">
  329. <button type="submit">Set latest</button>
  330. </form>
  331. <?php endif; ?>
  332. <form method="POST" style="display:inline" onsubmit="return confirm('Delete this release?');">
  333. <input type="hidden" name="action" value="delete">
  334. <input type="hidden" name="csrf_token" value="<?php echo updateManageEscape(updateManageCsrfToken()); ?>">
  335. <input type="hidden" name="version" value="<?php echo updateManageEscape($version); ?>">
  336. <button type="submit">Delete</button>
  337. </form>
  338. </td>
  339. </tr>
  340. <?php endforeach; ?>
  341. </tbody>
  342. </table>
  343. <?php endif; ?>
  344. <?php endif; ?>
  345. </body>
  346. </html>